Vulnerability Description
An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://colorful-quill-4fe.notion.site/CVE-2026-71626-API-Webhook-SSRF-via-Inter
- https://colorful-quill-4fe.notion.site/CVE-2026-71626-API-Webhook-SSRF-via-Inter
FAQ
What is CVE-2026-71626?
CVE-2026-71626 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components
How severe is CVE-2026-71626?
CVE-2026-71626 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-71626?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.